Scam of the week: My dentist needs remote computer access?
Last week my partner handed me her phone and asked three words we ask each other way too often these days: “Is this real?”
At a glance, the email was convincing. It looked like an invitation from her dentist’s office. The logo was right and it used their standard signature. It looked legit to me too.
After clicking the link, a loading page promised an “exclusive eCard” would download automatically, and three seconds later a file landed in her Downloads folder. That raised her alarm; invitations don’t download files. Instead of opening it, she came and found me. I’m a software engineer, so I could figure out what the file was without running it. Most people aren’t so lucky!
What was in the file?
The file contained a remote-access tool that IT teams use to control computers from afar. The software is real and properly signed. But it wasn’t needed to open an invitation from the dentist.
If she had double-clicked and followed the wizard, as the page politely instructed, a fraudster would have obtained control of her laptop. Her email, her bank, all of it.
When something felt wrong, my partner did what most people do – she asked someone she trusts. But we’re bombarded by scam attempts nearly every day, and this approach is far from reliable, and the stakes are too high to rely on catching every scam attempt.
What you can do to stay safe
My partner had an antivirus running, but it never made a sound. It wasn’t designed to. It analyzed the file and checked whether it was real, signed software, and it was. But today’s biggest risk is deception, and that needs context. An invitation from my partner’s dentist shouldn’t be asking her to install remote-control software.
My partner stayed safe the way most people do these days. She recognized something was wrong, and she asked someone she trusts (me!). But this approach isn’t reliable. We’re bombarded by scam attempts nearly every day, and the stakes are too high to count on catching them all.
I’m building Rebound AntiScam, an always-on scam protection app, so she doesn’t have to be suspicious all the time. She didn’t have it running that night, but went back and ran the email through our desktop app and it flagged the scam right away. Everyone should have protection like this, so staying safe doesn’t depend on catching every scam yourself.
What the industry can do to keep you safer
Remote-access vendors can make this harder. The remote access tool used in this scam was a real product. Legitimate remote-management tools should verify who signs up, throttle brand-new accounts, and add real friction before allowing unattended-access agents to operate on a stranger’s machine.








A brilliant post if i do say so myself 🤣